PatchSiren cyber security CVE debrief
CVE-2026-65673 Microsoft CVE debrief
Microsoft Entra Connect Elevation of Privilege Vulnerability allows an authorized attacker to elevate privileges locally due to improper neutralization of special elements used in an SQL command. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has provided an advisory and patch for this vulnerability. Affected systems require immediate attention to prevent local privilege escalation. Defenders should prioritize patching to version 2.6.84.0 or later and verify local inventory for affected versions.
- Vendor
- Microsoft
- Product
- Microsoft Entra Connect
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Microsoft Entra Connect deployments should assess exposure and prioritize patching to version 2.6.84.0 or later. They should also verify local inventory for affected versions and monitor for local exploitation attempts. Security teams and vulnerability management teams should review the CVE record and Microsoft advisory to understand the vulnerability and its potential impact.
Why it matters
CVE-2026-65673 is a HIGH severity vulnerability in Microsoft Entra Connect that allows local privilege escalation. Defenders should prioritize patching and verify local inventory for affected versions.
- Local privilege escalation requires verification
- Patching is required to remediate vulnerability
- Inventory checks are necessary to identify affected systems
Technical summary
The vulnerability exists in Microsoft Entra Connect Sync due to improper neutralization of special elements used in an SQL command. An authorized attacker can exploit this vulnerability to elevate privileges locally. The vulnerability has a CVSS score of 7.8 and is considered HIGH severity. Microsoft has provided an advisory and patch for this vulnerability, which defenders should apply to prevent local privilege escalation.
Defensive priority
Defenders should prioritize patching Microsoft Entra Connect to version 2.6.84.0 or later, and verify local inventory for affected versions.
Recommended defensive actions
- Patch Microsoft Entra Connect to version 2.6.84.0 or later
- Verify local inventory for affected versions
- Monitor for local exploitation attempts
Evidence notes
The CVE record and Microsoft advisory provide details on the vulnerability, but do not specify versions or provide additional context. The vulnerability exists in Microsoft Entra Connect Sync, and defenders should verify local inventory for affected versions. The CVE Program record, NIST NVD detail page, and Microsoft advisory offer further information on the vulnerability. However, the exact scope of affected systems and potential impact are not explicitly stated.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-65673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-65673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-65673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Microsoft Entra Connect Elevation of Privilege Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/65xxx/CVE-2026-65673.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65673
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.